1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

bugcheck error 0x0000000a

Discussion in 'Windows Server System' started by ivor_smith, 2004/11/24.

Thread Status:
Not open for further replies.
  1. 2004/11/24
    ivor_smith

    ivor_smith Inactive Thread Starter

    Joined:
    2004/11/24
    Messages:
    1
    Likes Received:
    0
    Can anyone help to identify the following bugcheck error.
    Windoes 2003 web server.
    Up until now has hung regularly about midday every four days.
    Memory has been changed.
    Today it crashed with a memory dump.
    Can anyone helpo to dicipher this:


    Event Type: Information
    Event Source: Save Dump
    Event Category: None
    Event ID: 1001
    Date: 24/11/2004
    Time: 13:09:22
    User: N/A
    Computer: ~~~~~~~
    Description:
    The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xff9b6000, 0x00000002, 0x00000000, 0x804fe140). A dump was saved in: C:\WINDOWS\MEMORY.DMP.
     
  2. 2004/11/24
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    please run that dump through the tool in my signature and post the results
     

  3. to hide this advert.

  4. 2004/11/30
    mblindt

    mblindt Inactive

    Joined:
    2004/11/30
    Messages:
    2
    Likes Received:
    0
    Any help would be greatly appreciated.



    Opened log file 'c:\debuglog.txt'
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

    Microsoft (R) Windows Debugger Version 6.3.0017.0
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINNT\MEMORY.DMP]
    Kernel Complete Dump File: Full address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINNT;C:\WINNT\system32;C:\WINNT\system32\drivers
    Windows 2000 Kernel Version 2195 (Service Pack 4) MP (4 procs) Free x86 compatible
    Product: LanManNt
    Kernel base = 0x80400000 PsLoadedModuleList = 0x80484980
    Debug session time: Tue Nov 30 13:00:01 2004
    System Uptime: 0 days 0:37:03.437
    Loading Kernel Symbols
    .............................................................................................
    Loading unloaded module list
    ......
    Loading User Symbols
    PEB address is NULL !
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {bad0b0e4, 2, 1, 8006543a}

    Probably caused by : ntkrnlmp.exe ( nt!KiTrap0E+210 )

    Followup: MachineOwner
    ---------

    3: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: bad0b0e4, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000001, value 0 = read operation, 1 = write operation
    Arg4: 8006543a, address which referenced memory

    Debugging Details:
    ------------------


    WRITE_ADDRESS: bad0b0e4 Nonpaged pool

    CURRENT_IRQL: 2

    FAULTING_IP:
    hal!KfAcquireSpinLock+1a
    8006543a f00fba2900 lock bts dword ptr [ecx],0x0

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xA

    LAST_CONTROL_TRANSFER: from 80414dcf to 8006543a

    STACK_TEXT:
    f244fd2c 80414dcf 00000000 813b79f0 bad0b0b0 hal!KfAcquireSpinLock+0x1a
    f244fd40 804d8269 bad0b0e4 00000001 813b7a08 nt!ExAcquireResourceExclusiveLite+0x1d
    f244fd60 8045030a 813b7a08 80485750 804778a0 nt!ObpRemoveObjectRoutine+0x47
    f244fd78 80417615 00000000 00000000 00000000 nt!ObpProcessRemoveObjectQueue+0x3e
    f244fda8 8045643c 00000000 00000000 00000000 nt!ExpWorkerThread+0xaf
    f244fddc 8046b4d6 80417566 00000000 00000000 nt!PspSystemThreadStartup+0x54
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


    FOLLOWUP_IP:
    nt!KiTrap0E+210
    80469d1c f7457000000200 test dword ptr [ebp+0x70],0x20000

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!KiTrap0E+210

    MODULE_NAME: nt

    IMAGE_NAME: ntkrnlmp.exe

    DEBUG_FLR_IMAGE_TIMESTAMP: 40d1d19a

    STACK_COMMAND: .trap fffffffff244fcbc ; kb

    BUCKET_ID: 0xA_BADMEMREF_nt!KiTrap0E+210

    Followup: MachineOwner
    ---------

    eax=8200813c ebx=0000000a ecx=00000001 edx=40000000 esi=8006543a edi=bad0b0e4
    eip=80469d1c esp=f244fca8 ebp=f244fcbc iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KiTrap0E+0x210:
    80469d1c f7457000000200 test dword ptr [ebp+0x70],0x20000 ss:0010:f244fd2c=00010246
    ChildEBP RetAddr Args to Child
    f244fcbc 8006543a 00065104 81400ba0 813fa000 nt!KiTrap0E+0x210 (FPO: [0,0] TrapFrame @ f244fcbc)
    f244fd2c 80414dcf 00000000 813b79f0 bad0b0b0 hal!KfAcquireSpinLock+0x1a (FPO: [0,0,0])
    f244fd40 804d8269 bad0b0e4 00000001 813b7a08 nt!ExAcquireResourceExclusiveLite+0x1d (FPO: [Non-Fpo])
    f244fd60 8045030a 813b7a08 80485750 804778a0 nt!ObpRemoveObjectRoutine+0x47 (FPO: [Non-Fpo])
    f244fd78 80417615 00000000 00000000 00000000 nt!ObpProcessRemoveObjectQueue+0x3e (FPO: [EBP 0xf244fda8] [1,0,4])
    f244fda8 8045643c 00000000 00000000 00000000 nt!ExpWorkerThread+0xaf (FPO: [Non-Fpo])
    f244fddc 8046b4d6 80417566 00000000 00000000 nt!PspSystemThreadStartup+0x54 (FPO: [Non-Fpo])
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
    start end module name
    80062000 80076460 hal halmacpi.dll Thu Mar 20 20:04:42 2003 (3E7A733A)
    80400000 805a00c0 nt ntkrnlmp.exe Thu Jun 17 12:15:06 2004 (40D1D19A)
    a0000000 a018e860 win32k win32k.sys Mon Aug 09 22:51:25 2004 (4118463D)
    f183a000 f1861420 nwrdr nwrdr.sys Fri Feb 21 11:08:23 2003 (3E565D07)
    f194a000 f1952240 Fips Fips.SYS Tue May 09 10:28:29 2000 (39182E9D)
    f1a1a000 f1a374a0 afd afd.sys Wed Apr 30 03:45:29 2003 (3EAF8D29)
    f1a38000 f1a4e400 nwlnkipx nwlnkipx.sys Wed Jan 15 13:56:26 2003 (3E25BCEA)
    f1a4f000 f1a67e00 nbf nbf.sys Sat Sep 25 14:16:47 1999 (37ED1F9F)
    f1ba8000 f1c0ec80 ati2drad ati2drad.dll Thu Dec 20 14:57:27 2001 (3C2250B7)
    f1c0f000 f1c24180 dump_atapi dump_atapi.sys Tue Apr 01 12:08:25 2003 (3E89D599)
    f1c4d000 f1cb3240 mrxsmb mrxsmb.sys Thu May 22 17:46:57 2003 (3ECD5361)
    f1cc6000 f1cf09c0 rdbss rdbss.sys Thu May 22 17:47:05 2003 (3ECD5369)
    f1cf1000 f1d33a80 vsdatant vsdatant.sys Tue Nov 02 10:25:00 2004 (4187B4DC)
    f1d34000 f1d5be00 netbt netbt.sys Wed Jul 16 14:44:26 2003 (3F15AB1A)
    f1d5c000 f1dad060 tcpip tcpip.sys Tue Apr 29 18:05:31 2003 (3EAF053B)
    f1e15000 f1e50bc0 srv srv.sys Tue Apr 29 18:05:07 2003 (3EAF0523)
    f1eb1000 f1edb3a0 update update.sys Tue Apr 15 23:22:01 2003 (3E9CDA69)
    f1edc000 f1ef7b40 ks ks.sys Tue Apr 15 23:02:11 2003 (3E9CD5C3)
    f1f20000 f1f36ba0 ndiswan ndiswan.sys Tue Apr 29 18:05:01 2003 (3EAF051D)
    f1f37000 f1f5b400 e100bnt5 e100bnt5.sys Thu Aug 19 15:26:54 2004 (41250D0E)
    f1f5c000 f1fa6d00 ati2mpad ati2mpad.sys Thu Dec 20 14:56:53 2001 (3C225095)
    f1fd0000 f1fd3580 vga vga.sys Sat Sep 25 13:37:40 1999 (37ED1674)
    f2000000 f200e6a0 pci pci.sys Wed Jan 15 13:44:07 2003 (3E25BA07)
    f2010000 f201b680 isapnp isapnp.sys Wed Jan 15 13:43:47 2003 (3E25B9F3)
    f2020000 f2028700 CLASSPNP CLASSPNP.SYS Wed Jan 15 13:42:51 2003 (3E25B9BB)
    f2040000 f204c4c0 VIDEOPRT VIDEOPRT.SYS Wed Jan 15 13:47:20 2003 (3E25BAC8)
    f2050000 f205b680 i8042prt i8042prt.sys Tue Apr 15 23:00:59 2003 (3E9CD57B)
    f2060000 f206f400 serial serial.sys Tue Apr 15 23:19:39 2003 (3E9CD9DB)
    f2070000 f207ca80 rasl2tp rasl2tp.sys Tue Apr 29 18:05:06 2003 (3EAF0522)
    f2080000 f208bc40 raspptp raspptp.sys Wed May 14 18:47:00 2003 (3EC2D574)
    f2090000 f209ea20 parallel parallel.sys Wed Jan 15 13:47:14 2003 (3E25BAC2)
    f20a0000 f20a9be0 usbhub usbhub.sys Tue Mar 18 17:30:41 2003 (3E77AC21)
    f20d0000 f20d9ce0 NDProxy NDProxy.SYS Thu Sep 30 18:25:35 1999 (37F3F16F)
    f20e0000 f20e8fa0 Npfs Npfs.SYS Sat Oct 09 18:58:07 1999 (37FFD68F)
    f20f0000 f20f8680 msgpc msgpc.sys Wed Jan 15 13:54:25 2003 (3E25BC71)
    f2100000 f21081a0 netbios netbios.sys Tue Oct 12 14:34:19 1999 (38038D3B)
    f2110000 f211e360 nwlnkspx nwlnkspx.sys Sat Sep 25 14:16:42 1999 (37ED1F9A)
    f21f0000 f21ffee0 nwlnknb nwlnknb.sys Wed Jan 15 13:56:27 2003 (3E25BCEB)
    f2280000 f2285520 PCIIDEX PCIIDEX.SYS Tue Feb 25 12:31:08 2003 (3E5BB66C)
    f2288000 f228f4c0 MountMgr MountMgr.sys Tue Feb 10 13:47:53 2004 (40293569)
    f2290000 f2297720 disk disk.sys Wed Jan 15 13:43:05 2003 (3E25B9C9)
    f2298000 f229ff40 uhcd uhcd.sys Wed Jan 15 13:45:50 2003 (3E25BA6E)
    f22a8000 f22afd00 wanarp wanarp.sys Fri Aug 16 07:25:01 2002 (3D5CEF1D)
    f22b0000 f22b4fc0 USBD USBD.SYS Wed Jan 22 11:05:33 2003 (3E2ECF5D)
    f22d8000 f22dd400 mouclass mouclass.sys Thu Feb 20 10:37:45 2003 (3E550459)
    f22e8000 f22edec0 kbdclass kbdclass.sys Thu Feb 20 10:37:30 2003 (3E55044A)
    f22f8000 f22fe580 fdc fdc.sys Wed Jan 15 13:42:51 2003 (3E25B9BB)
    f2310000 f2316100 parport parport.sys Wed Jan 15 13:47:13 2003 (3E25BAC1)
    f2320000 f2326c40 cdrom cdrom.sys Wed Jan 15 13:43:04 2003 (3E25B9C8)
    f2340000 f2344400 ptilink ptilink.sys Wed Jan 15 13:47:15 2003 (3E25BAC3)
    f2350000 f23540e0 raspti raspti.sys Fri Oct 08 15:45:10 1999 (37FE57D6)
    f2370000 f2374a60 flpydisk flpydisk.sys Wed Jan 15 13:42:52 2003 (3E25B9BC)
    f23e0000 f23e6a20 EFS EFS.SYS Wed Jan 15 13:46:55 2003 (3E25BAAF)
    f2400000 f2405240 Msfs Msfs.SYS Tue Oct 26 18:21:32 1999 (3816377C)
    f2410000 f2412a20 BOOTVID BOOTVID.dll Wed Nov 03 19:24:33 1999 (3820E051)
    f2414000 f2416d00 PartMgr PartMgr.sys Wed Jan 15 13:43:07 2003 (3E25B9CB)
    f24ac000 f24af640 serenum serenum.sys Wed Jan 15 13:47:01 2003 (3E25BAB5)
    f24b4000 f24b62e0 ndistapi ndistapi.sys Wed Jan 15 13:54:15 2003 (3E25BC67)
    f24c4000 f24c7e60 TDI TDI.SYS Wed Jan 15 13:56:26 2003 (3E25BCEA)
    f2500000 f2501d20 Diskperf Diskperf.sys Wed Feb 12 15:34:38 2003 (3E4ABDEE)
    f2502000 f2503b80 dmload dmload.sys Wed Jan 15 13:47:06 2003 (3E25BABA)
    f2512000 f2513ca0 Fs_Rec Fs_Rec.SYS Wed Jan 15 13:53:30 2003 (3E25BC3A)
    f251a000 f251be40 rasacd rasacd.sys Sat Sep 25 13:41:23 1999 (37ED1753)
    f2590000 f2591860 ParVdm ParVdm.SYS Mon Sep 27 22:28:16 1999 (37F035D0)
    f25c8000 f25c8f80 WMILIB WMILIB.SYS Sat Sep 25 13:36:47 1999 (37ED163F)
    f25c9000 f25c9b00 pciide pciide.sys Wed Jan 15 13:43:03 2003 (3E25B9C7)
    f25f2000 f25f2a40 audstub audstub.sys Sat Sep 25 13:35:33 1999 (37ED15F5)
    f25fc000 f25fcd80 swenum swenum.sys Sat Sep 25 13:36:31 1999 (37ED162F)
    f260c000 f260c9e0 Null Null.SYS Sat Sep 25 13:34:58 1999 (37ED15D2)
    f260e000 f260eee0 Beep Beep.SYS Wed Oct 20 17:18:59 1999 (380E3FD3)
    f2611000 f2611f80 mnmdd mnmdd.SYS Sat Sep 25 13:37:40 1999 (37ED1674)
    f263f000 f263ff80 dump_WMILIB dump_WMILIB.SYS Sat Sep 25 13:36:47 1999 (37ED163F)
    f66ff000 f670f760 NAVENG NAVENG.sys Thu Sep 30 20:59:17 2004 (415CB9F5)
    f67d8000 f6870680 NAVEX15 NAVEX15.sys Thu Sep 30 21:11:15 2004 (415CBCC3)
    f6899000 f68d7000 NAVAP NAVAP.sys Fri May 02 23:08:14 2003 (3EB340AE)
    f68d7000 f68e7a60 SYMEVENT SYMEVENT.SYS Wed May 14 00:45:43 2003 (3EC1D807)
    f6a30000 f6a3fa20 ipsec ipsec.sys Tue Apr 29 18:04:59 2003 (3EAF051B)
    f6b08000 f6b0b000 nwlnkflt nwlnkflt.sys Sat Sep 25 14:16:45 1999 (37ED1F9D)
    f6d28000 f6d30900 nwlnkfwd nwlnkfwd.sys Thu Nov 04 18:25:57 1999 (38222415)
    f6fc8000 f6fea3c0 Fastfat Fastfat.SYS Wed Jan 15 13:48:39 2003 (3E25BB17)
    f7153000 f7163520 ipnat ipnat.sys Mon Nov 11 16:04:45 2002 (3DD0297D)
    f74b4000 f74c5000 NAVAPEL NAVAPEL.SYS Fri May 02 23:08:21 2003 (3EB340B5)
    f757d000 f758bfe0 Cdfs Cdfs.SYS Tue Apr 15 22:58:53 2003 (3E9CD4FD)
    f8769000 f877e640 Mup Mup.sys Wed Jan 15 13:54:01 2003 (3E25BC59)
    f877f000 f87a8aa0 NDIS NDIS.sys Tue Apr 29 18:05:01 2003 (3EAF051D)
    f87a9000 f8826800 Ntfs Ntfs.sys Wed Jun 04 17:11:33 2003 (3EDE6E95)
    f8827000 f88387c0 KSecDD KSecDD.sys Sat Sep 20 19:32:19 2003 (3F6CF193)
    f8839000 f884b1c0 Dfs Dfs.sys Tue Feb 11 20:19:06 2003 (3E49AF1A)
    f884c000 f885e0c0 SCSIPORT SCSIPORT.SYS Fri May 16 20:11:02 2003 (3EC58C26)
    f885f000 f8871160 fasttrak fasttrak.sys Sun May 12 14:26:50 2002 (3CDEC1FA)
    f8872000 f8887180 atapi atapi.sys Tue Apr 01 12:08:25 2003 (3E89D599)
    f8888000 f88a99c0 dmio dmio.sys Wed Jan 15 13:47:04 2003 (3E25BAB8)
    f88aa000 f88c6220 ftdisk ftdisk.sys Mon Mar 31 16:21:58 2003 (3E88BF86)
    f88c7000 f88eec20 ACPI ACPI.sys Wed Jan 15 13:44:22 2003 (3E25BA16)

    Unloaded modules:
    f1df6000 f1e51000 dmboot.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1bfa000 f1c0f000 VGA.dll
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1ba8000 f1c0f000 ati2drad.dll
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f2110000 f2119000 redbook.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f23f0000 f23f5000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f1fd8000 f1fdb000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  5. 2004/11/30
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    hard to say for sure. probable pool corruption. Would need to perform advanced diagnostics on the dump to be sure.
    Need to enable pool tagging, and probably special pool.

    This is probably a good canidate to contact microsoft on.
     
  6. 2004/11/30
    mblindt

    mblindt Inactive

    Joined:
    2004/11/30
    Messages:
    2
    Likes Received:
    0
    ok. thanks.
     
  7. 2004/12/01
    bassinl

    bassinl Inactive

    Joined:
    2004/12/01
    Messages:
    5
    Likes Received:
    0
    finally

    Hi guys, got sent here by a google search. Ive had this same problem, so Ive done your steps you posted. Here is my txt. file, any help on this would be greatly appreciated.Opened log file 'c:\debuglog.txt'
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

    Microsoft (R) Windows Debugger Version 6.3.0017.0
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini120104-03.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows XP Kernel Version 2600 UP Free x86 compatible
    Product: WinNt
    Built by: 2600.xpclient.010817-1148
    Kernel base = 0x804d0000 PsLoadedModuleList = 0x80545b28
    Debug session time: Wed Dec 01 10:31:19 2004
    System Uptime: 0 days 0:45:12.047
    Loading Kernel Symbols
    ........................................................................................................
    Loading unloaded module list
    .........
    Loading User Symbols
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck A, {80bf2ff4, 2, 0, 804ed562}

    Probably caused by : memory_corruption ( nt!MiRemovePageByColor+16 )

    Followup: MachineOwner
    ---------

    kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    IRQL_NOT_LESS_OR_EQUAL (a)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If a kernel debugger is available get the stack backtrace.
    Arguments:
    Arg1: 80bf2ff4, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: 804ed562, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: 80bf2ff4

    CURRENT_IRQL: 2

    FAULTING_IP:
    nt!MiRemovePageByColor+16
    804ed562 8b7e0c mov edi,[esi+0xc]

    CUSTOMER_CRASH_COUNT: 3

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xA

    LAST_CONTROL_TRANSFER: from 804e97c5 to 804ed562

    TRAP_FRAME: f7c4679c -- (.trap fffffffff7c4679c)
    .trap fffffffff7c4679c
    ErrCode = 00000000
    eax=ffff3ffd ebx=00000000 ecx=80c53000 edx=00000002 esi=80bf2fe8 edi=0001bfba
    eip=804ed562 esp=f7c46810 ebp=ffffbfff iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010282
    nt!MiRemovePageByColor+0x16:
    804ed562 8b7e0c mov edi,[esi+0xc] ds:0023:80bf2ff4=????????
    .trap
    Resetting default scope

    STACK_TEXT:
    f7c46828 804e97c5 00000000 00008000 f7c46d38 nt!MiRemovePageByColor+0x16
    f7c4684c 80681f38 863ce790 00000000 00002649 nt!MmZeroPageThread+0xa1
    f7c46dac 80559026 80087000 00000000 00000000 nt!Phase1Initialization+0xe35
    f7c46ddc 8050f513 806800f7 80087000 00000000 nt!PspSystemThreadStartup+0x34
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


    FOLLOWUP_IP:
    nt!MiRemovePageByColor+16
    804ed562 8b7e0c mov edi,[esi+0xc]

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: nt!MiRemovePageByColor+16

    MODULE_NAME: nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 3b7de38f

    STACK_COMMAND: .trap fffffffff7c4679c ; kb

    IMAGE_NAME: memory_corruption

    BUCKET_ID: 0xA_nt!MiRemovePageByColor+16

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=0000000a ecx=00000000 edx=40000000 esi=804ed562 edi=80bf2ff4
    eip=804fc1bb esp=f7c46768 ebp=f7c46780 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x19:
    804fc1bb 5d pop ebp
    ChildEBP RetAddr Args to Child
    f7c46780 804d7c50 0000000a 80bf2ff4 00000002 nt!KeBugCheckEx+0x19 (FPO: [Non-Fpo])
    f7c46780 804ed562 0000000a 80bf2ff4 00000002 nt!KiTrap0E+0x2ad (FPO: [0,0] TrapFrame @ f7c4679c)
    f7c46828 804e97c5 00000000 00008000 f7c46d38 nt!MiRemovePageByColor+0x16 (FPO: [EBP 0x806b643c] [0,3,4])
    f7c4684c 80681f38 863ce790 00000000 00002649 nt!MmZeroPageThread+0xa1 (FPO: [EBP 0x00000000] [0,4,4])
    f7c46dac 80559026 80087000 00000000 00000000 nt!Phase1Initialization+0xe35 (FPO: [1,340,3])
    f7c46ddc 8050f513 806800f7 80087000 00000000 nt!PspSystemThreadStartup+0x34 (FPO: [Non-Fpo])
    00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
    start end module name
    804d0000 806b3f00 nt ntoskrnl.exe Fri Aug 17 23:39:59 2001 (3B7DE38F)
    806b4000 806d3700 hal halaacpi.dll Fri Aug 17 16:48:15 2001 (3B7D830F)
    9a7a6000 9a7f6a80 srv srv.sys Fri Aug 17 21:32:06 2001 (3B7DC596)
    9a81f000 9a849280 mrxdav mrxdav.sys Fri Aug 17 16:50:20 2001 (3B7D838C)
    9a88d000 9a8a0700 wdmaud wdmaud.sys Fri Aug 17 23:42:48 2001 (3B7DE438)
    9aa29000 9aa37080 sysaudio sysaudio.sys Fri Aug 17 23:47:26 2001 (3B7DE54E)
    9ac39000 9ac58e80 afd afd.sys Fri Aug 17 21:30:36 2001 (3B7DC53C)
    9acd1000 9acd3f80 ndisuio ndisuio.sys Fri Aug 17 16:53:53 2001 (3B7D8461)
    9ad99000 9adae280 dump_atapi dump_atapi.sys Fri Aug 17 16:51:49 2001 (3B7D83E5)
    9add7000 9ae3a880 mrxsmb mrxsmb.sys Fri Aug 17 23:31:45 2001 (3B7DE1A1)
    9ae3b000 9ae63000 rdbss rdbss.sys Fri Aug 17 23:44:30 2001 (3B7DE49E)
    9af03000 9af27b00 netbt netbt.sys Fri Aug 17 21:32:18 2001 (3B7DC5A2)
    9af28000 9af77e00 tcpip tcpip.sys Fri Aug 17 21:31:44 2001 (3B7DC580)
    bf800000 bf9b7580 win32k win32k.sys Fri Aug 17 23:52:56 2001 (3B7DE698)
    bf9b8000 bf9ef000 ati2dvag ati2dvag.dll Sat Jul 10 21:37:20 2004 (40F099D0)
    bf9ef000 bfa27000 ati2cqag ati2cqag.dll Sat Jul 10 21:19:21 2004 (40F09599)
    bfa27000 bfc354c0 ati3duag ati3duag.dll Sat Jul 10 21:34:09 2004 (40F09911)
    bfc36000 bfcb49a0 ativvaxx ativvaxx.dll Sat Jul 10 21:23:58 2004 (40F096AE)
    bff80000 bff90a80 dxg dxg.sys Fri Aug 17 17:55:56 2001 (3B7D92EC)
    f73b1000 f73d36c0 ATIRWVD ATIRWVD.SYS Mon Dec 15 06:27:40 2003 (3FDD9AAC)
    f73d4000 f73f5780 update update.sys Fri Aug 17 23:53:56 2001 (3B7DE6D4)
    f741e000 f744a580 rdpdr rdpdr.sys Fri Aug 17 16:50:45 2001 (3B7D83A5)
    f744b000 f745b180 psched psched.sys Fri Aug 17 16:54:25 2001 (3B7D8481)
    f74fc000 f7511900 ndiswan ndiswan.sys Fri Aug 17 21:30:58 2001 (3B7DC552)
    f7512000 f7524980 parport parport.sys Fri Aug 17 16:50:05 2001 (3B7D837D)
    f7525000 f7545f80 portcls portcls.sys Fri Aug 17 23:31:59 2001 (3B7DE1AF)
    f7546000 f7565d00 ks ks.sys Wed Dec 04 12:09:38 2002 (3DEE36D2)
    f7566000 f7584180 USBPORT USBPORT.SYS Fri Aug 17 17:03:07 2001 (3B7D868B)
    f7585000 f7656000 ati2mtag ati2mtag.sys Sat Jul 10 21:37:01 2004 (40F099BD)
    f7676000 f7678280 rasacd rasacd.sys Fri Aug 17 16:55:39 2001 (3B7D84CB)
    f769e000 f76b7600 Mup Mup.sys Fri Aug 17 23:21:29 2001 (3B7DDF39)
    f76b8000 f76df700 NDIS NDIS.sys Fri Aug 17 21:31:13 2001 (3B7DC561)
    f76e0000 f7762400 Ntfs Ntfs.sys Fri Aug 17 21:33:04 2001 (3B7DC5D0)
    f7763000 f7776780 KSecDD KSecDD.sys Fri Aug 17 16:50:01 2001 (3B7D8379)
    f7777000 f7788300 sr sr.sys Fri Aug 17 17:00:38 2001 (3B7D85F6)
    f7789000 f779e280 atapi atapi.sys Fri Aug 17 16:51:49 2001 (3B7D83E5)
    f779f000 f77c2b80 dmio dmio.sys Fri Aug 17 16:58:27 2001 (3B7D8573)
    f77c3000 f77e1880 ftdisk ftdisk.sys Fri Aug 17 16:52:41 2001 (3B7D8419)
    f77e2000 f780dc00 ACPI ACPI.sys Fri Aug 17 16:57:52 2001 (3B7D8550)
    f782f000 f783e400 pci pci.sys Fri Aug 17 16:58:04 2001 (3B7D855C)
    f783f000 f7847c00 isapnp isapnp.sys Fri Aug 17 16:58:01 2001 (3B7D8559)
    f784f000 f7858280 MountMgr MountMgr.sys Fri Aug 17 16:47:36 2001 (3B7D82E8)
    f785f000 f786b000 VolSnap VolSnap.sys Fri Aug 17 16:53:19 2001 (3B7D843F)
    f786f000 f7877380 disk disk.sys Fri Aug 17 16:52:31 2001 (3B7D840F)
    f787f000 f7889f80 CLASSPNP CLASSPNP.SYS Fri Aug 17 21:32:31 2001 (3B7DC5AF)
    f78df000 f78eee00 VIDEOPRT VIDEOPRT.SYS Fri Aug 17 16:57:42 2001 (3B7D8546)
    f78ef000 f78fb700 i8042prt i8042prt.sys Fri Aug 17 23:44:51 2001 (3B7DE4B3)
    f78ff000 f790a880 L8042pr2 L8042pr2.Sys Wed Dec 17 14:38:10 2003 (3FE0B0A2)
    f790f000 f791e760 LMouFlt2 LMouFlt2.Sys Wed Dec 17 14:38:27 2003 (3FE0B0B3)
    f791f000 f7928980 Imapi Imapi.SYS Fri Aug 17 16:53:17 2001 (3B7D843D)
    f792f000 f793a980 cdrom cdrom.sys Fri Aug 17 16:52:25 2001 (3B7D8409)
    f793f000 f794ca00 redbook redbook.sys Fri Aug 17 16:51:37 2001 (3B7D83D9)
    f794f000 f7959b00 viaudio viaudio.sys Tue Mar 12 02:27:19 2002 (3C8DADD7)
    f795f000 f796d000 drmk drmk.sys Fri Aug 17 17:01:08 2001 (3B7D8614)
    f796f000 f7978e00 fetnd5b fetnd5b.sys Fri Jul 05 06:12:57 2002 (3D257129)
    f797f000 f798e400 serial serial.sys Fri Aug 17 23:27:19 2001 (3B7DE097)
    f798f000 f799ae00 rasl2tp rasl2tp.sys Fri Aug 17 21:30:47 2001 (3B7DC547)
    f799f000 f79a8800 raspppoe raspppoe.sys Fri Aug 17 16:55:33 2001 (3B7D84C5)
    f79af000 f79ba580 raspptp raspptp.sys Fri Aug 17 21:30:51 2001 (3B7DC54B)
    f79bf000 f79c7400 msgpc msgpc.sys Fri Aug 17 16:54:19 2001 (3B7D847B)
    f79cf000 f79d8380 termdd termdd.sys Fri Aug 17 16:46:42 2001 (3B7D82B2)
    f79df000 f79e8480 NDProxy NDProxy.SYS Fri Aug 17 16:55:30 2001 (3B7D84C2)
    f7a0f000 f7a1b600 usbhub usbhub.sys Fri Aug 17 17:03:11 2001 (3B7D868F)
    f7a2f000 f7a3cb00 ipsec ipsec.sys Fri Aug 17 21:30:42 2001 (3B7DC542)
    f7a3f000 f7a47180 netbios netbios.sys Fri Aug 17 16:54:00 2001 (3B7D8468)
    f7a4f000 f7a57880 Fips Fips.SYS Fri Aug 17 21:31:49 2001 (3B7DC585)
    f7a5f000 f7a67200 wanarp wanarp.sys Fri Aug 17 16:55:23 2001 (3B7D84BB)
    f7a6f000 f7a7e300 Cdfs Cdfs.SYS Fri Aug 17 23:33:34 2001 (3B7DE20E)
    f7a7f000 f7a8e980 Udfs Udfs.SYS Fri Aug 17 16:49:58 2001 (3B7D8376)
    f7aaf000 f7ab4c80 PCIIDEX PCIIDEX.SYS Fri Aug 17 16:51:46 2001 (3B7D83E2)
    f7ab7000 f7abb900 PartMgr PartMgr.sys Fri Aug 17 21:32:23 2001 (3B7DC5A7)
    f7abf000 f7ac5b00 viaagp viaagp.sys Fri Aug 17 16:58:00 2001 (3B7D8558)
    f7ac7000 f7aced80 viaagp1 viaagp1.sys Wed Jul 24 05:44:31 2002 (3D3E76FF)
    f7b07000 f7b0e780 processr processr.sys Fri Aug 17 16:48:32 2001 (3B7D8320)
    f7b0f000 f7b13a00 usbuhci usbuhci.sys Fri Aug 17 17:03:04 2001 (3B7D8688)
    f7b17000 f7b1c600 mouclass mouclass.sys Fri Aug 17 16:47:50 2001 (3B7D82F6)
    f7b1f000 f7b24b80 kbdclass kbdclass.sys Fri Aug 17 16:47:47 2001 (3B7D82F3)
    f7b27000 f7b28000 fdc fdc.sys unavailable (00000000)
    f7b2f000 f7b33580 ptilink ptilink.sys Fri Aug 17 16:49:53 2001 (3B7D8371)
    f7b37000 f7b3b080 raspti raspti.sys Fri Aug 17 16:55:32 2001 (3B7D84C4)
    f7b3f000 f7b43d00 flpydisk flpydisk.sys Fri Aug 17 16:51:21 2001 (3B7D83C9)
    f7b4f000 f7b53c80 vga vga.sys Fri Aug 17 16:57:51 2001 (3B7D854F)
    f7b57000 f7b5b680 Msfs Msfs.SYS Fri Aug 17 16:50:02 2001 (3B7D837A)
    f7b5f000 f7b66380 Npfs Npfs.SYS Fri Aug 17 16:50:03 2001 (3B7D837B)
    f7c3f000 f7c42000 BOOTVID BOOTVID.dll Fri Aug 17 16:49:09 2001 (3B7D8345)
    f7cc7000 f7cca900 watchdog watchdog.sys Fri Aug 17 16:59:35 2001 (3B7D85B7)
    f7cdb000 f7cdea80 serenum serenum.sys Fri Aug 17 16:50:13 2001 (3B7D8385)
    f7cdf000 f7ce1600 gameenum gameenum.sys Fri Aug 17 17:02:29 2001 (3B7D8665)
    f7ce3000 f7ce5580 ndistapi ndistapi.sys Fri Aug 17 16:55:29 2001 (3B7D84C1)
    f7ce7000 f7ceaf80 TDI TDI.SYS Fri Aug 17 16:57:25 2001 (3B7D8535)
    f7d2f000 f7d30b80 kdcom kdcom.dll Fri Aug 17 16:49:10 2001 (3B7D8346)
    f7d31000 f7d32100 WMILIB WMILIB.SYS Fri Aug 17 17:07:23 2001 (3B7D878B)
    f7d33000 f7d34800 viaidexp viaidexp.sys Thu Oct 18 02:12:14 2001 (3BCE72BE)
    f7d35000 f7d36700 dmload dmload.sys Fri Aug 17 16:58:15 2001 (3B7D8567)
    f7d43000 f7d44280 USBD USBD.SYS Fri Aug 17 17:02:58 2001 (3B7D8682)
    f7d45000 f7d46f00 Fs_Rec Fs_Rec.SYS Fri Aug 17 16:49:37 2001 (3B7D8361)
    f7d47000 f7d48080 Beep Beep.SYS Fri Aug 17 16:47:33 2001 (3B7D82E5)
    f7d49000 f7d4a080 mnmdd mnmdd.SYS Fri Aug 17 16:57:28 2001 (3B7D8538)
    f7d4b000 f7d4c080 RDPCDD RDPCDD.sys Fri Aug 17 16:46:56 2001 (3B7D82C0)
    f7d51000 f7d52100 dump_WMILIB dump_WMILIB.SYS Fri Aug 17 17:07:23 2001 (3B7D878B)
    f7d95000 f7d96a80 ParVdm ParVdm.SYS Fri Aug 17 16:49:49 2001 (3B7D836D)
    f7f21000 f7f21c00 audstub audstub.sys Fri Aug 17 16:59:40 2001 (3B7D85BC)
    f7f26000 f7f27000 swenum swenum.sys Wed Dec 04 12:10:07 2002 (3DEE36EF)
    f7f2a000 f7f2ab80 Null Null.SYS Fri Aug 17 16:47:39 2001 (3B7D82EB)
    f7f6a000 f7f6ad00 dxgthk dxgthk.sys Fri Aug 17 16:53:12 2001 (3B7D8438)

    Unloaded modules:
    9a487000 9a4ae000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    9a84a000 9a871000 kmixer.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7f1c000 f7f1d000 drmkaud.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    9a871000 9a88d000 aec.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    9aa09000 9aa16000 DMusic.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    9aa19000 9aa27000 swmidi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7d8b000 f7d8d000 splitter.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f7b47000 f7b4c000 Cdaudio.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    f767a000 f767d000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  8. 2004/12/01
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    bassinl - you have memory corruption, and you are woefully out of date on windows update and security patches. The only driver on your machine that is up to date is your video card, heh. Get current on your software, service packs and drivers first, collect new data, and then post a new thread if you are still having crashes.
     
  9. 2004/12/01
    bassinl

    bassinl Inactive

    Joined:
    2004/12/01
    Messages:
    5
    Likes Received:
    0
    Well thanks for the info, Ive updated all of the security and other patchs. SP2 was unable to install for some reason, "invalid key ". Heck I don't know. But this is what I get now:

    Opened log file 'c:\debuglog.txt'
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

    Microsoft (R) Windows Debugger Version 6.3.0017.0
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini120104-06.dmp]
    Could not open dump file [C:\WINDOWS\Minidump\Mini120104-06.dmp], Win32 error 1392
    "The file or directory is corrupted and unreadable. "
    System still crashs to desk top, no error no nothing just crash.
    Little background info for you:
    I just recently installed more memory and a new graphics card
    1gig memory 3200 ddr on a mobo that supports up to 2100, this is ok aint it?
    new radeon ATI 9550 256mb mem. card

    Could these crashs be related to insuficient power? W/o opening the case im not sure of the power supply amount, anyway to tell w/o opening it again?

    LOL lot of questions, if anyone has any answers Id appreciate anything you got.
    Thanks :)

    Oh ya, Ive ran Memtest86 on my new memory sticks to see if it maybe was bad. Passed on 2 complete runs.
     
  10. 2004/12/01
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    bassinl Can you post a screenshot or the exact text you are receiving when trying to install sp2. Your software is out of date, and there is no point in trying to fix it until you get the latest code with all the bug fixes.
     
  11. 2004/12/01
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    bassinl - you won't be able to post the screen shot directly to the forum (staff, team members, contributing members only) but if you don't have web space where you can, attach it to email to me and I'll post it for you. Just put a copy of this url in the email so I don't have to fumble around trying to find out where it belongs.

    Probably best to mail me a copy to both the listed addresses since otherwise I might be a few hours getting to it.
     
  12. 2004/12/01
    bassinl

    bassinl Inactive

    Joined:
    2004/12/01
    Messages:
    5
    Likes Received:
    0
    Ok heres the latest, this is what I get from the MSupdate site.

    " The product key used to install Microsoft Windows XP may not be valid. For more information about why you have recieved the error message, and steps you can take to resolve this issue visit www.howtotell.com. "

    Seems as if my product key is not valid, dont understand how Ive gotten all the other updates if it wasn't. So is there any way to resolve my crash problem without SP2? I mean how would someone have done it prior to SP2? Once again thanks guys for taking the time to respond.
     
  13. 2004/12/01
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    You need to follow the directions, and go to howtotell.com to run the Windows Validation Assistant This site will help you understand the problem you are experiencing, and how to resolve it.

    Once you have that straightened out, then we can assist. A lot of the problem with doing this advanced level of diagnostics over the internet is that if you don't have exactly the right code, we are fishing in the dark for an answer. You have a piece of software, maybe even windows itself that is corrupting memory. Getting the OS up to date is just the first of a many step process, unfortunatly.
     
  14. 2004/12/01
    bassinl

    bassinl Inactive

    Joined:
    2004/12/01
    Messages:
    5
    Likes Received:
    0
    Well I guess Im just out of luck! Even the validation tool wont open for me, so no check no SP2. Did everything it said to do in concerns with active x configuration. How would someone without a internet (unable to update) fix this issue? Just seems that there should be away to resolve this issue without SP2 and or the latest updates. Heck not everyone, believe it or not, is connected online.
     
  15. 2004/12/02
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    They would get the free SP2 CD from Microsoft, and install it...

    No, there isn't.
     
  16. 2004/12/02
    bassinl

    bassinl Inactive

    Joined:
    2004/12/01
    Messages:
    5
    Likes Received:
    0
    Besides searching MS's web site, is there a link I could get you to write down to apply for this SP2 disc?
     
  17. 2004/12/02
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.